Skip to content
Intelligibberish
  • News
  • Articles
  • Guides
  • Tools
  • About

Tag

#vulnerabilities

← All articles

Privacy May 27, 2026

AI Security Roundup: Glasswing Finds 10,000 Zero-Days, Exploit Window Goes Negative

Anthropic's Mythos finds 10,000+ critical vulnerabilities but fewer than 1% get patched. Mandiant says exploits now arrive a week before fixes.

Privacy May 19, 2026

AI Security Roundup: One Million Exposed Services and the Teenager Problem

Intruder scanned 2 million hosts and found 1 million exposed AI services with no authentication. Plus: teenagers are using ChatGPT to hack governments, and OpenAI launches Daybreak.

Privacy May 6, 2026

AI Security Roundup: OpenClaw's Nine CVEs in Four Days

OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.

Analysis Apr 29, 2026

92% of AI-Generated Code Has Critical Vulnerabilities

Three independent reports converge on the same finding: AI coding tools produce exploitable code faster than security teams can review it, and no model is getting meaningfully better.

Privacy Apr 28, 2026

AI Security Roundup: Vercel Breached Through AI Tool, n8n's CVSS 10 Nightmare, and the Supply Chain Keeps Breaking

An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.

Privacy Apr 25, 2026

AI Security Roundup: Lovable's 48-Day Open Door, MCP Remote Code Execution, and NIST Abandons 29,000 CVEs

A vibe-coding platform exposed every project's secrets through a trivial API flaw, Anthropic's MCP protocol enables remote code execution across 200,000 servers, and NIST can't keep up with AI-driven vulnerability discovery.

Privacy Apr 20, 2026

AI Security Roundup: Vercel Breached Through an AI Tool, North Korea Weaponized Dependabot, and Your Bot Just Auto-Merged Malware

A third-party AI tool compromise chains into Vercel's systems, North Korean hackers use Dependabot to distribute malware to 895 repos, and courts fine lawyers $145K for AI hallucinations in Q1 alone.

Privacy Apr 17, 2026

AI Security Roundup: Mercor's 4TB Breach, n8n and Langflow RCEs, and the Week AI Workflow Tools Became Attack Surfaces

A supply chain attack exposes 40,000 AI contractors, three major workflow platforms get critical RCE flaws, and Microsoft patches 167 vulnerabilities as AI-driven discovery triples submission rates.

Privacy Apr 11, 2026

AI Security Roundup: Mythos Finds Thousands of Zero-Days, Vibe-Coded CVEs Surge, Flowise Under Active Attack

Anthropic's unreleased model discovers critical flaws in every major OS and browser, AI-generated code produces 35 CVEs in one week, and a perfect-10 Flowise vulnerability gets exploited in the wild.

Privacy Apr 6, 2026

AI Security Roundup: Azure AI Foundry Scores a Perfect 10, Langflow Hijacked in 20 Hours, LiteLLM's Backdoor Cleanup

Microsoft's Azure AI Foundry hit with a maximum-severity privilege escalation, Langflow exploited within hours of disclosure, and LiteLLM discloses three vulnerabilities after surviving a supply chain attack.

Privacy Apr 6, 2026

OpenClaw's Security Meltdown: 9 CVEs in 4 Days, 135K Exposed Instances, and a Poisoned Marketplace

The fastest-growing GitHub project ever just became the biggest AI agent security disaster of 2026. Here's what happened and why it matters.

Privacy Apr 4, 2026

AI Security Roundup: Claude Code Leak Weaponized for Malware, CrewAI's Four Unpatched Flaws

Threat actors turned Anthropic's accidental source code leak into a malware delivery pipeline within hours. Meanwhile, four unpatched CrewAI vulnerabilities let attackers chain prompt injection into full remote code execution.

Privacy Apr 1, 2026

9 CVEs in 4 Days: OpenClaw's Security Crisis Deepens

OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.

Privacy Mar 31, 2026

OpenClaw: The AI Agent That Broke Every Record and Then Broke Security

The fastest-growing open source project in GitHub history has become 2026's first major AI security disaster, with 135,000+ exposed instances, 9 CVEs in 4 days, and malware-laced skills.

Privacy Mar 29, 2026

AI Security Roundup: TeamPCP Strikes Telnyx, LangChain/LangGraph Vulnerabilities Expose Enterprise Data

TeamPCP's supply chain campaign continues with a WAV file steganography attack on Telnyx. Meanwhile, three vulnerabilities in LangChain and LangGraph can leak files, secrets, and conversation histories.

Privacy Mar 28, 2026

AI Coding Tools Are Flooding Open Source With Security Holes

Georgia Tech researchers tracking real CVEs find 35 vulnerabilities from AI-generated code in March alone—and estimate the actual number is 10x higher.

Privacy Mar 27, 2026

OpenClaw: How the Hottest AI Agent Became a Security Nightmare in Three Weeks

135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.

Privacy Mar 25, 2026

AI Security Roundup: TeamPCP's Supply Chain Rampage, LiteLLM Poisoned, Langflow Exploited in 20 Hours

A coordinated supply chain campaign has compromised Trivy, LiteLLM, and dozens of npm packages. Meanwhile, Langflow attackers built working exploits within hours of disclosure.

Privacy Mar 25, 2026

AI Security Roundup: Trivy Supply Chain Attack Spawns Self-Spreading Worm, Langflow Exploited in 20 Hours

Security scanners become attack vectors, AI agent platforms get RCE'd before patches exist, and 400+ GitHub repos fall to GlassWorm. Plus: a new secrets scanner built for AI coding agents.

Privacy Mar 23, 2026

Images That Hijack AI: Visual Prompt Injection Achieves 90% Attack Success

New research reveals multimodal LLMs are vulnerable to hidden instructions embedded in images. Mind maps, steganography, and physical signage all bypass text-based safety filters.

Privacy Mar 23, 2026

AI Agents Are Being Hijacked in the Wild: 22 Attack Techniques Now Documented

Unit 42 researchers catch indirect prompt injection attacks actively weaponizing AI agents on live websites, from forced transactions to data exfiltration

Privacy Mar 23, 2026

Langflow Under Attack: Critical RCE Exploited Within 20 Hours of Disclosure

A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.

Privacy Mar 23, 2026

OpenClaw's CVE Avalanche: 156 Security Advisories, 28 Published Vulnerabilities, and Counting

The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.

Privacy Mar 21, 2026

AI Security Roundup: Meta's Rogue Agent, PleaseFix Vulnerabilities, and LRMs That Jailbreak Other AIs

A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.

← Newer1 / 2Older →
Intelligibberish

Independent analysis and commentary on artificial intelligence.

News Articles Guides Tools About Disclosure Privacy RSS

© 2026 Intelligibberish. Signal, not noise.